Security Policy Enforcement for Removable Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a growing need for enhanced computer protection systems to prevent theft of confidential information and harm to computer equipment or files, as existing systems are inadequate in addressing the increasing number of computer threats.
Innovation Solution
A method and computer program product assess the security compliance state of a client computing facility by comparing its configuration information with a security policy, blocking communication with removable storage devices if out of compliance, including USB, serial, parallel, and Bluetooth ports, to prevent data leakage and external threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system blocks communication with removable storage devices when security compliance is violated, then data leakage and malware spread are prevented, but device functionality and user productivity are reduced
Solution Approach 1:
The system dynamically adjusts security controls based on real-time compliance status. When a device is out of compliance, access to removable storage devices is blocked; when compliance is restored, access is automatically restored. This dynamic adaptation allows the system to maintain security without permanently reducing functionality.
Solution Approach 2:
The system changes the security parameter (access permission) based on the compliance state. By monitoring compliance parameters such as antivirus updates, patch levels, and security configurations, the system modifies the access parameter to block or allow device connections accordingly.
2Reliability
If the system continuously monitors security compliance state, then security protection is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system implements a feedback loop where compliance status is continuously monitored and reported back to the security management system. This feedback mechanism enables automatic enforcement actions without requiring complex manual intervention or overly complicated monitoring architectures.
Solution Approach 2:
The monitored device performs self-assessment of its security compliance state by checking its own configuration, updates, and security settings. This self-service approach reduces the complexity of centralized monitoring while maintaining effective security oversight.
Data Source
AI summary
Embodiments of the present invention extend the enforcement of computer security policies by blocking device access as well as network access. In some embodiments, communications with external devices are blocked upon discovery that some aspect of the client computing facility is out of compliance vis-à-vis a security policy.


